Courseiva

NSE4 Firewall Policies and NAT Practice Question

You run the following command on a FortiGate: 'diagnose sys session filter dport 443' and see: proto=6 proto_state=01 duration=3600 expire=3599 What does this output indicate?

⚠ Common exam trap

The trap here is that candidates see `duration=3600` and `expire=3599` and assume the session is established and about to expire, but the `proto_state=01` (SYN_SENT) clearly indicates the handshake is incomplete, not that the session is active or being torn down.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session is in SYN_SENT state and the three-way handshake is not yet complete

The output shows `proto=6`, which indicates TCP, and `proto_state=01`, which corresponds to the TCP state SYN_SENT (0x01). This means the session has sent a SYN but has not yet received a SYN-ACK, so the three-way handshake is incomplete. The `duration=3600` and `expire=3599` indicate the session has been tracked for 3600 seconds and will expire in 3599 seconds, but the state confirms it is not yet established.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The session is in SYN_SENT state and the three-way handshake is not yet complete

    Why this is correct

    In FortiOS session table output, the proto_state field for TCP is shown in hex; a value of 01 corresponds to SYN_SENT (0x01), meaning the initial SYN packet was sent but the SYN-ACK has not yet been received. This indicates the three-way handshake is still in progress and the session is not yet established. Therefore, the correct interpretation is that the connection is incomplete.

  • ✗

    The session is using UDP and the duration is 3600 seconds

    Why it's wrong here

    The protocol column in the diagnose sys session output uses IP protocol numbers, and proto=6 specifically identifies TCP, not UDP (which would be proto=17). While the duration field does display 3600 seconds, that reflects the session's age since creation, but the transport protocol is definitively TCP, so the session cannot be UDP. The combination of proto=6 and proto_state=01 clearly rules out this option.

  • ✗

    The session is being torn down and will expire in 3599 seconds

    Why it's wrong here

    The Expire field in the session table shows the remaining lifetime in seconds before the session is removed from the table, not the teardown status of the session. A value of 3599 simply means the session was created one second ago and has 3599 seconds left on its idle timer; it does not indicate a teardown in progress. Also, a session in SYN_SENT state is young, not in a termination phase.

  • ✗

    The session is fully established and has been active for 3600 seconds

    Why it's wrong here

    A TCP session in the FortiOS session table is only considered fully established when proto_state shows ESTABLISHED, which is typically represented as 06 (or 0x06) in hex, not 01. The value 01 corresponds to SYN_SENT, the very first state of the handshake. Although the Duration field shows 3600 seconds, that is merely the session age and says nothing about the handshake state, so this session is not established.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.